Re: ntopng LDAPS/RADIUS Auth

Simone Mainardi <[email protected]> Mon, 11 Nov 2019 09:55:18 +0100
Newsgroups gmane.linux.ntop.general
Message-ID <[email protected]>
--===============3221671403280693457==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_EA176C05-3321-4800-B982-01585BC4C198"


--Apple-Mail=_EA176C05-3321-4800-B982-01585BC4C198
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Hi,

> On 9 Nov 2019, at 22:10, Ken Kirchner <[email protected]> wrote:
>=20
> Hello,
>=20
> I am trying to setup ntopng to use LDAPS on my Pro licensed version.  =
I have put in all the parameters, but it does not work.  Since I am =
using LDAPS and not LDAP, do I need to load certificates on the ntopng =
server (RHEL7)?

Did you try and specify ldaps:// in the server address? Please, look at =
the ntopng output, see if there are any errors, and post them here.

You may want to follow these resources:
- =
https://www.ntop.org/ntopng/remote-ntopng-authentication-with-radius-and-l=
dap/ =
<https://www.ntop.org/ntopng/remote-ntopng-authentication-with-radius-and-=
ldap/>
- =
https://www.ntop.org/guides/ntopng/advanced_features/authentication.html?h=
ighlight=3Dldap#ldap-authentication =
<https://www.ntop.org/guides/ntopng/advanced_features/authentication.html?=
highlight=3Dldap#ldap-authentication>

Specifically, you can also try and test the connection using the `ldap` =
command if you are on linux.

Issue may be related to: https://stackoverflow.com/a/17078646

>=20
>=20
> On my non-licensed ntopng servers I have successfully configured =
RADIUS authentication (well, the admin group filter doesnt work, but I =
dont really care) but it is only using PAP.  Does ntopng support any =
encrypted protocols?

Only PAP. If you need other protocols, please open a FR on GitHub and we =
will consider it.

Simone

>=20
> -Ken K.
>=20
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop


--Apple-Mail=_EA176C05-3321-4800-B982-01585BC4C198
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Hi,<br class=3D""><div><br class=3D""><blockquote type=3D"cite"=
 class=3D""><div class=3D"">On 9 Nov 2019, at 22:10, Ken Kirchner &lt;<a =
href=3D"mailto:[email protected]" class=3D"">[email protected]</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div =
class=3D"">Hello,<br class=3D""><br class=3D"">I am trying to setup =
ntopng to use LDAPS on my Pro licensed version. &nbsp;I have put in all =
the parameters, but it does not work. &nbsp;Since I am using LDAPS and =
not LDAP, do I need to load certificates on the ntopng server =
(RHEL7)?<br class=3D""></div></div></blockquote><div><br =
class=3D""></div><div>Did you try and specify ldaps:// in the server =
address? Please, look at the ntopng output, see if there are any errors, =
and post them here.</div><div><br class=3D""></div><div>You may want to =
follow these resources:</div><div>-&nbsp;<a =
href=3D"https://www.ntop.org/ntopng/remote-ntopng-authentication-with-radi=
us-and-ldap/" =
class=3D"">https://www.ntop.org/ntopng/remote-ntopng-authentication-with-r=
adius-and-ldap/</a></div><div>-&nbsp;<a =
href=3D"https://www.ntop.org/guides/ntopng/advanced_features/authenticatio=
n.html?highlight=3Dldap#ldap-authentication" =
class=3D"">https://www.ntop.org/guides/ntopng/advanced_features/authentica=
tion.html?highlight=3Dldap#ldap-authentication</a></div><div><br =
class=3D""></div><div>Specifically, you can also try and test the =
connection using the `ldap` command if you are on linux.</div><div><br =
class=3D""></div><div>Issue may be related to:&nbsp;<a =
href=3D"https://stackoverflow.com/a/17078646" =
class=3D"">https://stackoverflow.com/a/17078646</a></div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D""><div =
class=3D""><br class=3D""><br class=3D"">On my non-licensed ntopng =
servers I have successfully configured RADIUS authentication (well, the =
admin group filter doesnt work, but I dont really care) but it is only =
using PAP. &nbsp;Does ntopng support any encrypted protocols?<br =
class=3D""></div></div></blockquote><div><br class=3D""></div>Only PAP. =
If you need other protocols, please open a FR on GitHub and we will =
consider it.</div><div><br class=3D""></div><div>Simone<br class=3D""><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D""><div =
class=3D""><br class=3D"">-Ken K.<br class=3D""><br =
class=3D"">_______________________________________________<br =
class=3D"">Ntop mailing list<br class=3D""><a =
href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a><br =
class=3D"">http://listgateway.unipi.it/mailman/listinfo/ntop<br =
class=3D""></div></div></blockquote></div><br class=3D""></body></html>=

--Apple-Mail=_EA176C05-3321-4800-B982-01585BC4C198--

--===============3221671403280693457==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
--===============3221671403280693457==--